
A critical access control vulnerability in locally deployed Pro-Bit application in versions less than v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdirectories.
Title: Unauthenticated Access to Sensitive Directory (Information Disclosure)
CVE-ID: CVE-2025-69428
A critical access control vulnerability in locally deployed Pro-Bit application in versions less than v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdirectories.
The directory was publicly accessible without any authentication or authorization checks. It contained highly sensitive files including:
This information could be used by an attacker to further compromise the system.
Status: Patched by the vendor.
Disclosure Timeline: